Back to skill

Security audit

Workflow Dlc Agent Learning

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill is not malware, but it asks agents to broadly log user interactions and send periodic reports without enough privacy controls.

Review this before installing in any environment with customer, employee, compliance, financial, or other sensitive data. Only use it with explicit logging notice, data minimization, redaction of raw user inputs where possible, strict report recipients, retention limits, and a clear way to disable or scope the logging workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly requires automatic logging of every interaction and includes sensitive fields such as user_input, agent_parse, form_filled, user_modified, compliance decisions, geo data, and contextual metadata. Collecting and persisting this data without any notice, consent boundary, minimization guidance, or redaction controls creates a meaningful privacy and data-governance risk, especially because the design encourages broad capture as a P0 requirement.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The workflow states that AI-generated summaries derived from logged interaction data are pushed to Feishu, but it provides no safeguards around what data is included, who receives it, or whether sensitive content is sanitized first. This increases the risk of secondary disclosure of personal, operational, or compliance-sensitive information to broader audiences or external systems through routine report distribution.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.